Vault - crontab (scheduled jobs)
Vault Solution · Config document · referenced from Audit logging and log shipping, Monitoring and day-2 operations
The system crontab of a Vault node. The last job exists only on Vault nodes; the others are on every server.
| Item | Value |
|---|---|
| Path on the host | /etc/crontab |
| Shown here | Vault node |
| Deployed on | every server, without the last job on load balancers and bastion hosts |
The file
#------------------------------------------------------------------------------ # File: crontab # Description: periodic jobs configuration via CRON # Author: admin01 # Date: 2024 # # REF1: man 5 crontab # REF2: https://crontab.guru #------------------------------------------------------------------------------ #------------------------------------------------------------------------------ # Examples #------------------------------------------------------------------------------ # .---------------- minute (0 - 59) # | .------------- hour (0 - 23) # | | .---------- day of month (1 - 31) # | | | .------- month (1 - 12) OR jan,feb,mar,apr ... # | | | | .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat # | | | | | # * * * * * user-name command to be executed #------------------------------------------------------------------------------ # Basic settings #------------------------------------------------------------------------------ SHELL=/bin/bash PATH=/sbin:/bin:/usr/sbin:/usr/bin MAILTO=root #------------------------------------------------------------------------------ # Jobs #------------------------------------------------------------------------------ # Update the security-scan client package if available (daily at 23:30) 30 23 * * * root yum update scan-client -y # Regular security scan (daily at 00:00) 00 00 * * * root /opt/scan-client/client.sh # Regular daily CRON jobs (daily at 00:00) 00 00 * * * root nice run-parts /etc/cron.daily # Regular weekly CRON jobs (every Sunday at 00:00) 00 00 * * 0 root nice run-parts /etc/cron.weekly # Regular monthly CRON jobs (first day of the month at 00:01) 01 00 1 * * root nice run-parts /etc/cron.monthly # Storing Vault logs to S3 storage (daily at 07:00) 00 07 * * * root /usr/local/bin/vault-logs-s3-sync.sh